Re: Follow up - PHP Security problems
| From: | MrBaseball34 | Date: | Wed, 07 Nov 2001 17:34:40 +0000 |
| Subject: | Re: Follow up - PHP Security problems | ||
| References: | 1 2 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-73766@lists.php.net to get a copy of this message | ||
> Instead of referencing the actual filename of the image in the source file
> (from here known as "SrcFile"), reference a file (from here known as
> "ImgFile") that will grab the image. Use an encryption method in the
> SrcFile to create a value that corresponds to the image you want to display,
> and pass that value to the ImgFile. The ImgFile will decrypt the code, grab
> the appropriate image, and return the image to the SrcFile. So, instead of
> seeing <img src="one.gif"><img src="two.gif"> in the SrcFile,
> all you see is
> <img src="ImgFile.php3?img=102342143"><img
> src="ImgFile.php3?img=342014253">
> - and those "img=" values are constantly changing!
>
But that would still allow them to get the code. You need to NOT have a
refereence to the code that was written in the image, You can have a
variable that references the code in the image to a record in a DB, that
would be how you would actually do the lookup to see if what they typed
is the same as the one they were presented.
The hacker would not have access to your DB to get the code but your PHP
script would.